Pushing on String: The 'Don't Care' Region of Password Strength.

The article discusses the efficacy of methods for defending password-protected networks from guessing attacks, including enterprises that impose stringent password-composition policies. Topics include research suggesting that stringent passwords do not always reduce the likelihood of successful gues...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 59; no. 11; pp. 66 - 75
Autores principales: FLORÊNCIO, DINEI, HERLEY, CORMAC, VAN OORSCHOT, PAUL C.
Formato: Artículo
Publicado: Association for Computing Machinery Nov2016
Materias:
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:The article discusses the efficacy of methods for defending password-protected networks from guessing attacks, including enterprises that impose stringent password-composition policies. Topics include research suggesting that stringent passwords do not always reduce the likelihood of successful guessing attacks, the use of phishing email messages once an attacker has access to an internal account, and differences in the password strength required to resist online and offline guessing attacks.